Aggregator
CVE-2025-25872 | OpenPanel 0.3.4 permission (EUVD-2025-6440)
Акция: купи Лабубу, получи в подарок… взлом Telegram
Critical Roundcube Flaw Allows Remote Code Execution by Attackers
Roundcube Webmail, one of the most widely used browser-based IMAP clients, has released urgent security updates for its 1.6 and 1.5 LTS versions. The newly published versions, 1.6.11 and 1.5.10, address a critical post-authentication remote code execution (RCE) vulnerability stemming from PHP object deserialization. This flaw, reported by security researcher firs0v, could allow attackers with […]
The post Critical Roundcube Flaw Allows Remote Code Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New Study Reveals Vulnerable Code Pattern Putting GitHub Projects at Risk of Path Traversal Attacks
A comprehensive research study has identified a widespread path traversal vulnerability (CWE-22) affecting 1,756 open-source GitHub projects, some of which are highly influential in the software ecosystem. The vulnerability, present in a commonly used Node.js code pattern for creating static HTTP file servers, enables attackers to access files outside of restricted locations, potentially compromising confidentiality […]
The post New Study Reveals Vulnerable Code Pattern Putting GitHub Projects at Risk of Path Traversal Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2012-1898 | Ivano Binetti Wolf CMS up to 0.75 cross site scripting (EDB-18652)
CVE-2025-0324 | Axis Communications AB AXIS OS up to 11.11.139/12.3.32 VAPIX Device Configuration Framework incomplete filtering of special elements
CVE-2025-0325 | Axis Communications AB AXIS OS up to 8.40.73/9.80.99/10.12.277/11.11.141/12.4.27 Guard Tour VAPIX API improper validation of specified type of input
CVE-2025-0358 | Axis Communications AB AXIS OS up to 12.3.x VAPIX Device Configuration Framework privileges management
Veiligheid Europa en Indo-Pacific onlosmakelijk verbonden
Теперь мы живем в интерфейсе — ChatGPT выходит за пределы экрана
CVE-2024-57062 | SoundCloud App 7.65.2 on iOS user session (EUVD-2025-6393)
CVE-2025-29032 | Tenda AC9 15.03.05.19 formWifiWpsOOB buffer overflow (EUVD-2025-6428)
CVE-2025-29030 | Tenda AC6 15.03.05.16 formWifiWpsOOB buffer overflow (EUVD-2025-6430)
CVE-2025-29031 | Tenda AC6 15.03.05.16 fromAddressNat buffer overflow (EUVD-2025-6429)
CVE-2025-29029 | Tenda AC6 15.03.05.16 formSetSpeedWan buffer overflow (EUVD-2025-6431)
CVE-2025-25748 | HotelDruid 3.0.7 gestione_utenti.php cross-site request forgery (EUVD-2025-6419)
CVE-2025-5113 | Diviotec nbr222p up to 2.0170.3030 command injection
CVE-2025-4010 | Netcomm NTC 6200/NWL-222 Web Interface command injection
Severe Vulnerabilities in Consilium CS5000 Fire Panels Allow Remote System Takeover
Two severe cybersecurity vulnerabilities have been disclosed in the Consilium Safety CS5000 Fire Panel, a widely deployed industrial control system integral to fire safety across sectors like commercial facilities, healthcare, transportation, and government services. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued alert ICSA-25-148-03 on May 29, 2025, warning that these flaws could enable […]
The post Severe Vulnerabilities in Consilium CS5000 Fire Panels Allow Remote System Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.